CVE-2021-39935

high KEV
Published 2026-02-03 · Modified 2026-02-03
CVSS v3
CVSS v2
VIR risk
9.5

Description

GitLab Community and Enterprise Editions contain a server-side request forgery vulnerability which could allow unauthorized external users to perform Server Side Requests via the CI Lint API.

CISA KEV

Vendor
GitLab
Product
Community and Enterprise Editions
Due date
2026-02-24

Predictions

Exploit likelihood
99%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cisa-kev — https://about.gitlab.com/releases/2021/12/06/security-release-gitlab-14-5-2-released/ ; https://nvd.nist.gov/vuln/detail/CVE-2021-39935

vendor Authored 2026-05-27

Vendor advisory: arch — https://security.archlinux.org/ASA-202112-10

Exploits

OS impact

OSVersionStatusFixed in
arch archfixed14.5.2-1

References

Verify integrity in audit chain (admin only). AS-IS.